Today's briefing
The Setting Nobody Checked
Mistral now trains on what users type unless they pay for the enterprise tier. The lesson isn't about one vendor — it's about defaults you never agreed to.
The one that matters
Mistral will train on what your staff type in — unless you are on the enterprise plan
Mistral, the French AI company whose models sit inside a growing number of European and Indian business tools, has changed a default. Text that users type into its products is now used to train its models. Enterprise-tier customers are exempt. Everybody else is opted in until they go and opt out.
That is the entire story. It is worth understanding precisely, because the useful part is not really about Mistral.
What this means for your business
Think about what your staff actually paste into a chat box on a normal Tuesday. At a 600-student school, the office manager pastes three parent complaint emails and asks for a polite reply — full names, class sections, sometimes a line about unpaid fees. At a 30-bed clinic, the front desk pastes a discharge summary and asks for a simpler version the family can follow. At a workshop with 40 staff, the owner pastes three supplier quotations to compare unit prices, then pastes the salary sheet to check a bonus calculation.
Not one of those people made a decision about data policy. They opened a cheap or free account, often a personal one on their own phone, and got the work done. The vendor's default setting decided everything after that.
The realistic exposure is not that a competitor types a question and receives your supplier quotation back. That is not how these systems work, and anyone telling you otherwise is selling something. The real issue is duller and harder to undo: text you never intended to publish has left your control and entered a training corpus you cannot inspect, audit or recall. For a clinic, that is a patient-confidentiality problem whether or not anything ever leaks. For a school holding records on minors, it is a question your management committee will eventually ask. Your obligations under Canadian privacy law, or under India's data protection rules, do not shift because a vendor changed a checkbox in a settings page.
What this is not
This is not a breach, a hack, or evidence that AI tools are unsafe to use. Your files are not becoming searchable. Most vendors, including this one, offer a business tier where training on your input does not happen — the safe configuration exists, it simply is not what you get by default.
Two groups will overstate this. Consultants will offer you a data-sovereignty audit for a fee that exceeds what you spend on the tools themselves. And vendors will pitch private or on-premise AI as the only responsible choice, when for most businesses a paid tier and a one-page rule about what never goes into a chat box does the same job for a fraction of the money.
What a sensible owner does this month
- List what your staff actually use, including personal accounts. Ask them directly; do not check the IT inventory, which will be wrong.
- Open the settings page of each tool and find the training or data-improvement toggle. Turn it off. This takes about ten minutes per tool.
- Write one page naming what must never be pasted anywhere: patient identifiers, student records, salary data, bank details, unsigned contracts.
- Pay for the business tier on the two or three tools that touch real customer data. The price varies by vendor, so check your invoice rather than a blog post.
- Put a reminder in the diary for six months out to check the same toggles again. Defaults change quietly, and this will not be the last time.
An afternoon of somebody's time, plus one or two tier upgrades. That is the whole response. Anyone quoting you a project should be asked what else they are including.
Also worth knowing
-
Anthropic reverses a data retention change after customers object, and ships new models
Anthropic reportedly rolled back a change to how long it keeps customer data after paying customers pushed back, and released new Claude models in the same week. The rollback is the part worth noting: it shows these terms move under commercial pressure rather than on a fixed schedule. If a vendor's data handling is load-bearing for your compliance story, get it written into your contract instead of trusting a policy page that can be edited overnight.
Stocktwits ↗ -
Anthropic restarts outside security testing after its models were used in attacks
Anthropic has resumed external cyber-security testing following incidents in which its Claude models were used in hacking activity. Nothing here changes what you do on Monday morning. It does confirm the direction of travel: the same tools drafting your quotations are getting better at writing convincing attacks, so re-run the boring rule that nobody changes a supplier's bank details without a phone call to a number you already had.
The Economic Times ↗ -
Sony and Warner sue Anthropic over music used to train its models
Two of the largest music companies are suing Anthropic over songs used in training. This matters if you are generating audio for ads, reels or on-hold music, because the legal status of what these tools produce is genuinely unsettled and a small business is a bad candidate to become a test case. For anything that plays in public or in a paid campaign, licensed stock music remains the cheap answer.
The Hindu ↗ -
Three sites built 215,128 fake buying-guide pages to be quoted by AI assistants
Three websites generated over 215,000 "best software" pages aimed squarely at AI assistants, and Perplexity cites them. Answer engines are being farmed the same way Google search was fifteen years ago, which means the recommendation your customer receives may be an advertisement wearing a review's clothes. Spend twenty minutes asking the main assistants about your category and your business name, and see what comes back.
Hacker News ↗ -
A Copilot flaw let researchers pull data out and corrupt what it remembered
Researchers demonstrated a flaw, nicknamed CoSnitch, that tricked Microsoft Copilot into leaking data and poisoning its stored memory. This is relevant if you run Microsoft 365 and have pointed Copilot at company mail and shared drives. Patching is Microsoft's job; deciding which folders Copilot is allowed to read is yours, and most businesses have given it far more access than the work requires.
The Cool Down ↗ -
Google ships cheaper fast models, including a security-focused variant
Google released Gemini 3.8 Flash along with a Flash Cyber version. Flash-class models are the cheap, quick tier, and their pricing is what decides whether high-volume routine work — sorting inbound enquiries, tagging invoices, drafting first-pass support replies — is worth automating at all. If someone quoted you for that kind of automation six months ago and it looked too expensive, the arithmetic has probably changed.
Hacker News ↗ -
New York City moves to ban AI in its public schools
New York's mayor is banning AI use in city schools. It binds nobody in India or Canada, but school operators in both countries should expect the same argument at their next board or parent meeting. Far better to have a written position on what staff and students may use, and why, before someone drafts one for you in a hurry.
Hacker News ↗ -
OpenAI publishes a customer story about three days of work done in three hours
OpenAI has put out a case study about an events company compressing three days of marketing and merchandising work into three hours, including turning product photos into an inventory site in fifteen minutes. Read it as what it is: a vendor's best case, selected and narrated by the vendor. The underlying pattern is real enough — small marketing teams are getting quicker at repetitive production work — but the multiple is a sales figure, not a forecast for your business.
OpenAI ↗
How this briefing is put together
Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.